Description
This vulnerability allows a malicious actor with access to add or modify content in an instance of the Backstage software catalog to inject script URLs in the entities stored in the catalog. If users of the catalog then click on said URLs, that can lead to an XSS attack.
Recommendation
Update the @backstage/catalog-model package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.2.0
- Patched version(s): 1.2.0
References
Related Issues
- Cross site scripting Vulnerability in backstage Software Catalog - @backstage/core-components - CVE-2023-25571
- angular-ui-notification Cross-site Scripting vulnerability - CVE-2023-34840
- @excalidraw/excalidraw Cross-site Scripting vulnerability - CVE-2023-26140
- Layui cross-site scripting (XSS) vulnerability - CVE-2023-50550
You might also like:
- Tags:
- npm
- @backstage/catalog-model
Anything's wrong? Let us know Last updated on February 14, 2023


